The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.
History

Wed, 14 Aug 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens jt2go
Siemens teamcenter Visualization
CPEs cpe:2.3:a:siemens:jt2go:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:teamcenter_visualization:*:*:*:*:*:*:*:*
Vendors & Products Siemens
Siemens jt2go
Siemens teamcenter Visualization
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 12 Aug 2024 22:00:00 +0000

Type Values Removed Values Added
Description The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.
Title Siemens Teamcenter Visualization and JT2Go Out-of-bounds Read
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2024-08-12T21:46:38.910Z

Updated: 2024-08-14T14:02:45.201Z

Reserved: 2023-12-21T19:40:53.933Z

Link: CVE-2023-7066

cve-icon Vulnrichment

Updated: 2024-08-14T14:02:31.105Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-12T22:15:08.770

Modified: 2024-08-13T12:58:25.437

Link: CVE-2023-7066

cve-icon Redhat

No data.